A vendor-neutral technology leadership playbook covering transaction due diligence, Day 1 continuity, integration, standardisation and clean divestment/separation.
Process map
AssessDue diligence
risk / cost
risk / cost
PlanDay 1
decision rights
decision rights
StabiliseAccess / support
critical services
critical services
IntegrateSystems / data
people / suppliers
people / suppliers
StandardiseCore platforms
process / controls
process / controls
SeparateData / identity
contracts / TSA
contracts / TSA
OperateBAU ownership
measures / backlog
measures / backlog
Technology due diligence
- Map the application landscape, critical dependencies, ownership, lifecycle and duplicated capability.
- Assess infrastructure, cloud, resilience, identity, privileged access and material technical debt.
- Review cybersecurity, privacy, regulatory obligations and unresolved control gaps.
- Understand data ownership, quality, transfer constraints, retention requirements and reporting dependencies.
- Review vendor concentration, contract renewal dates, change-of-control clauses, exit provisions and hidden dependencies.
- Identify key-person dependency, outsourced capability, support coverage and transition risk.
Day 1 readiness
- Prioritise continuity and control rather than immediate standardisation.
- Confirm identity/access, connectivity, critical applications, support paths, monitoring and executive communications.
- Make known risks explicit: accepted, treated, transferred or escalated.
Integration and standardisation
- Use strategic fit, security, cost, user impact, data/integration complexity and supportability to decide what should be retained, consolidated, replaced or retired.
- Stabilise first, then converge deliberately. A parent platform should not automatically win simply because it is already there.
Divestment and separation
- Map shared applications, data stores, identities, networks, licences, suppliers and support arrangements before committing exit dates.
- Treat data separation as a controlled workstream: what transfers, what remains, what must be retained and what must be destroyed.
- Use Transitional Service Agreements only where immediate separation is impractical, with clear service, security, cost and exit terms.
- Validate that interfaces, scheduled jobs, accounts, remote access and reporting feeds have been removed or redirected.
- Retain evidence of final access removal, data transfer/destruction, contract closure and operational sign-off.
Governance
- Use clear decision rights, RACI, RAID, critical-path planning, change control and executive/SteerCo escalation.
- Make the future BAU owner part of the integration or separation work rather than handing over at the end.
Key lessons
- Divestment is not acquisition in reverse; separation needs its own control model.
- Day 1 is about continuity and control, not instant standardisation.
- Technology due diligence should influence the transaction, not merely document the environment afterwards.
- Standardise the core and govern justified exceptions.